Home · Solutions · HR & people
Solution · HR & peopleAccounts, roles and equipment ready before day one, and switched off the day someone leaves
Joiner, mover, leaver: access on day one, revoked same day
One HR event provisions every account, licence, group, system role and piece of equipment, and the same pipeline revokes all of it on the leaving date, with evidence.
Executive summary
New starters wait days for access; leavers keep theirs for weeks. Both are the same missing handover.
The design rests on one principle: employment is declared in exactly one place and everything else reacts to it.
People work on day one.
Microsoft Entra ID and Microsoft 365; SAP S/4HANA users and roles; warehouse and till applications
Business problem
Employee lifecycle
Three events run the working life of every employee: they join, they move, they leave. Each sets off work in ten to fifteen systems, and each system has a different owner, request channel and definition of done. HR owns the contract, IT owns the directory, the manager owns whether the person can do the job on Monday, facilities owns the badge. Nobody owns the sequence, which is what breaks.
Joiners are the visible failure. Someone who cannot work on day one is paid anyway, so is the colleague covering, and in a store the lost day is a shift on the roster. Managers compensate with a private checklist and a lot of chasing.
Movers are the quiet failure: new access is urgent, old access is nobody's ticket, and entitlements accumulate until the most experienced people hold the combined rights of every job they have held. Leavers are the expensive one. Notice travels through payroll on its own schedule, so a departed employee keeps a working VPN profile, an SAP user and a licence for weeks, and nobody can show an auditor when anything was switched off.
How it works today
A form emailed by HR is the only thing tying the steps below together, at most large employers, whatever the HR system.
- PersonHR records the hire, transfer or termination and emails a form to the service desk and to facilities
- WaitingThe request queues behind incident work; accounts appear a day or two before the start date, sometimes after it
- PersonAn agent creates the identity, assigns the licence and copies group membership from a colleague who "does something similar"
- SystemSAP roles, the warehouse application, the till account, VPN and telephony are separate tickets with separate approvers
- PersonThe manager keeps a private checklist and chases whatever is missing by day three
- Risk of errorInternal moves add new rights and leave the old ones in place, so entitlements grow with every job change
- Risk of errorLeavers are disabled when the message gets through; VPN, SAP and smaller applications survive until the next access review
- WaitingEquipment and badges are ordered by email, without a due date
Why the current process costs more than it appears
The cost grows where nobody is looking.
- Coordination is the real work, not the clicking. Every event touches HR, the service desk, the manager and facilities, and the hours spent chasing between them never become a ticket.
- Unrevoked accounts are billed twice: as a licence you keep paying for, and as access that should not exist. Neither surfaces until the annual true-up or a penetration test.
- Accumulated entitlements erode control silently. The finding lands at the audit, months after the combination became possible, and remediation costs far more than removal.
- Managers rebuild the same knowledge on every hire. What a store systems analyst needs sits in one person's sent items, not in a definition the company can reuse.
- Answering "does this person still have access to SAP?" takes three teams and a day, which turns every audit sample into an investigation.
Cost of inaction
Hours are the cheap part of this problem. What compounds is entitlement drift: every move that adds rights without removing any takes the company further from the access picture it believes it has, and the correction is an access-review project rather than a click. Each leaver whose VPN outlives their employment is an open question that becomes expensive on the day someone asks it.
There is also a hiring cost that never appears as one. When day one reliably means day three, induction is improvised and the new employee's first impression is a service-desk queue, formed roughly 110 times a month at 22% turnover.
A plausible organisation with realistic proportions. The figures are there to be recalculated on your data; they are not a client result.
A retail and logistics group, 6,500 employees across stores, distribution centres and a head office in four countries; SAP SuccessFactors as the HR system of record, SAP S/4HANA in finance, Microsoft 365 with Microsoft Entra ID for the office and management population.
240 joiner, mover and leaver events a month at 22% annual turnover, roughly 110 joiners, 70 internal moves and 60 leavers, touching fourteen systems and four badge estates.
Forms travel from HR into a service-desk queue; identities and licences are set up by hand, SAP roles and VPN in separate tickets, equipment and badges by email, and every manager runs a personal checklist.
About two and a half hours of coordination per event across the four teams, plus a revocation step that depends on someone remembering on the right day.
The HR record becomes the only trigger. Microsoft Entra ID Governance lifecycle workflows handle the Microsoft 365 identity, UiPath robots handle every system without a connector, the manager gets one checklist in Microsoft Teams, and the leaving date runs a revocation sequence that writes its own evidence.
In the modelled case, 600 hours a month of coordination are released, joiners start with working access on the start date, and revocation moves from "when someone remembers" to the date in the HR record. The figures are a model, not a measurement.
Proposed solution
The design rests on one principle: employment is declared in exactly one place and everything else reacts to it. A hire, transfer or termination in the HR system is the only event that starts work. No starter form, no parallel spreadsheet, no second definition of a start date, which is also what makes the process auditable.
The Microsoft 365 half is native. Microsoft Entra ID Governance lifecycle workflows run joiner, mover and leaver templates from attribute triggers in the HR data: create the identity, issue a Temporary Access Pass, assign licences and group and Teams membership, and on the leaving date remove licences, strip membership and disable the account. This requires a Microsoft Entra ID Governance or Microsoft Entra Suite licence for every user in scope, which is a real cost line and belongs in the business case rather than a footnote.
Everything else is ours. Most companies run a dozen systems with no lifecycle connector: SAP users and roles, the warehouse application, the till estate, VPN, telephony, badges, procurement. UiPath robots do that work deterministically from the same access profile, called through an Azure Logic Apps task extension, while UiPath Maestro keeps one case per person and event, so a Monday starter is a single object with deadlines rather than eleven tickets. The manager sees one checklist in their Teams channel; anything outside the profile becomes an approval to the system owner.
Microsoft Entra ID Governance lifecycle workflows (joiner, mover and leaver templates, attribute triggers, Temporary Access Pass, group and Teams membership, licence removal, account disable); Azure Logic Apps custom task extensions; Microsoft Teams Approvals app; Microsoft Planner tasks through Microsoft Graph; UiPath Orchestrator queues, credential stores and audit
The access profile catalogue mapping job families to entitlements, the Maestro case that carries each event end to end, the robots for every non-integrated system, the manager checklist and its escalations, the leaving-day revocation sequence with its evidence pack, and the monthly reconciliation
SAP user and role administration through UiPath SAP activities and connectors; VPN, warehouse and till systems through their own interfaces, or their user interface where none exists; badge and equipment requests into facilities and procurement
How the automated process works
- AutomationA hire, transfer or termination in SAP SuccessFactors fires an attribute trigger; Maestro opens one case with the start or leaving date as its deadline
- AutomationThe lifecycle workflow runs the Microsoft 365 part on the start date: identity, Temporary Access Pass, licences, groups, Teams membership, welcome sequence
- SystemRobots provision every system without a connector from the same profile: SAP roles, warehouse and till accounts, VPN, telephony, shared drives, each with its own retry
- AutomationEquipment and badge requests go to procurement and facilities with the cost centre from the HR record; confirmed dates return into the case
- PersonThe manager gets one Microsoft Planner checklist in Teams: buddy, first-week plan, safety briefing, sign-in confirmed; overdue items escalate
- PersonAccess beyond the profile, and leaving-date exceptions, are approvals in Microsoft Teams to the system owner
- AutomationOn the leaving date the sequence disables sign-in, strips group and role membership, reclaims the licence, converts the mailbox, locks the SAP user, revokes the VPN certificate and books the badge and laptop return, one timestamped record per step
- AutomationMonthly, the pipeline compares HR records against Microsoft Entra ID, SAP users and the other systems, and reports every identity with no employment record
Human-in-the-loop model
Automation handles
- Provisioning timed to the start date, and removal timed to the leaving date
- System access derived from job data in the HR record: position, department, location, cost centre
- Equipment orders, badge requests and return bookings, with the cost centre from the record
- The evidence: what was granted, under which rule, who approved exceptions, when each revocation completed
People decide
- Access beyond the profile, approved in Teams by the system owner within their delegated authority
- Whether a mover keeps anything from the previous role, and for how many days
- Leaving-date exceptions: a restricted notice period, garden leave, a dispute, a rehire
- The access profile catalogue, owned by the business rather than by the service desk
Before and after
Systems and integrations
Everything below runs on licences and systems you already hold, or would need anyway.
Inputs
- SAP SuccessFactors hire, transfer and termination records
- the access profile catalogue
- manager and cost-centre data
- the equipment standard
Automation layer
- Entra ID Governance lifecycle workflows
- Azure Logic Apps
- UiPath Maestro
- UiPath Orchestrator
- UiPath Robots
- UiPath Action Center
Target systems
- Microsoft Entra ID and Microsoft 365
- SAP S/4HANA users and roles
- warehouse and till applications
- VPN and telephony
- badges
- procurement
Human touchpoints: Teams Approvals for out-of-profile access; the manager's Planner checklist; Action Center exception tasks
Technologies used
account, Temporary Access Pass, licences, groups, Teams membership, disable and delete
Acustom task extensions called from the lifecycle workflow, and the hand-off into UiPath
Aprovisioning and revocation in SAP, warehouse, till, VPN, telephony, badge and procurement systems; queues, credentials, audit
Aone long-running case per person and event: sequence, waits, deadlines, escalations
Aapprovals and exception tasks completed without leaving Teams
Athe manager's day-one checklist and its due dates
Athe employment record that triggers everything; SAP user and role administration
Aprovisioning lead time, revocation timeliness and exception volumes
AIllustrative economic model
A model, not a promise.
Treat the 150 minutes as a placeholder you can replace: it is the coordination effort for a whole event across HR, the service desk, the line manager and facilities, including chasing and rework, and it is an illustrative figure from typical ranges, not a measurement at a client. €30 is a blended fully loaded hourly cost for those roles in Central Europe. The result is capacity released, not a headcount reduction.
Run the numbers on your data
An illustrative estimate from your own inputs. It models released capacity; it is not a promise of savings.
Business benefits
- People work on day one. Access exists before the person arrives, so the first day is induction, not a service-desk queue.
- The leaving date means something. Sign-in, VPN, SAP and the smaller applications end on the date in the HR record, with proof of the hour.
- Internal moves stop adding rights: a transfer removes the previous profile as deliberately as it grants the new one.
- Licences follow real headcount, reclaimed on the leaving date rather than at the annual true-up.
- Managers run one checklist in Teams instead of four channels, and see only what needs a human.
- Hiring peaks need no extra service-desk capacity: a store opening runs through the same pipeline as a single hire.
The management view
- The lifecycle becomes a service with a lead time, a completion rate and a visible queue, not an assumption that IT will manage.
- Access is defined once per job and reviewed by the system owners, so a new country or store reuses definitions.
- Evidence for auditors is produced by the process in the moment, not assembled by hand before a review.
- The company can answer on any day who has access to what, and prove that the people who left do not.
Board-level KPIs
Security and governance
An auditor should be able to reconstruct every decision.
- Each robot holds its own named account per system with only the rights that step needs; secrets stay in the platform credential store or your enterprise vault, never in a script
- Every grant and revocation writes an immutable line: the rule behind it, the approver of any exception, the system touched and the time it completed, which turns offboarding into evidence rather than assertion
- Identity and employment data stays in your Microsoft 365 tenant and HR system; orchestration runs in the UiPath Automation Cloud EU region
- Segregation of duties is enforced by the flow: the requester of out-of-profile access is never its approver
- Privileged roles are excluded from automatic assignment; they follow the approval path under Microsoft Entra Privileged Identity Management
Why now
EU cybersecurity law treats this as a baseline duty: Article 21(2) of Directive (EU) 2022/2555 lists human resources security, access control policies and asset management among the minimum risk-management measures, and supervisors ask for evidence rather than intention
Turnover in retail and logistics makes the lifecycle a production line, not an occasional event; in the modelled group it runs at €18,000 a month before anyone counts a licence
The Microsoft 365 half is configuration rather than development: lifecycle workflows cover joiner, mover and leaver natively and call Azure Logic Apps for the rest, so custom code is confined to systems with no interface
Relevant executive roles
The HR record starts and ends employment everywhere, so HR stops being the place managers chase for IT
One provisioning path with a full audit trail replaces a dozen ticket queues and copied memberships
Licences and equipment follow real headcount, and a cost never on a budget line becomes visible
A store opening or a seasonal intake is staffed without the service desk becoming the constraint
Common questions and objections
Then the reconciliation is the first deliverable, because it shows exactly which records and which identities disagree. Groups typically find a few hundred mismatches in month one and a handful by month three; the data improves because something finally depends on it.
A ticket workflow tells a person what to do next; this does the work and proves it was done. The service desk keeps the exceptions, which is where their judgement is worth paying for.
Lifecycle workflows require Microsoft Entra ID Governance or Microsoft Entra Suite, licensed for every user in scope, and that belongs in the business case openly. Where the licence is not justified, the same sequence can run from UiPath against Microsoft Graph: less native tooling, more that we build.
When this is not the right solution
- Fewer than roughly thirty lifecycle events a month, where one clear owner and a good checklist beat a provisioning platform
- The HR system is not the record of hires and terminations, or the record appears after the start date; fix that at the source first
- Access cannot be described by job. If entitlements are negotiated person by person, the first project is an access review and a role model
A question for the next management meeting
If we ended an employment record this afternoon, how many hours would pass before every account, role and key belonging to that person stopped working, and could we prove it?
Implementation approach
The first week looks the same at every client: we look at the data.
We deliver
- The access profile catalogue: job families mapped to Microsoft 365 groups, SAP roles, system accounts, VPN profiles and the equipment standard
- Configuration of Entra ID Governance lifecycle workflows for joiner, mover and leaver, with the Temporary Access Pass and the timing rules
- Azure Logic Apps task extensions and the hand-off into UiPath for systems with no lifecycle connector
- Robots for SAP users and roles, warehouse and till systems, VPN, telephony, badges, equipment orders
- The Maestro case per person and event, with deadlines, escalations and the manager checklist
- The leaving-day revocation sequence with its evidence pack, and the monthly reconciliation
- Pilot on one country, then rollout with hypercare and a runbook for the service desk
We need from you
- The HR data model: which fields declare a hire, a transfer and a termination, and how early they are reliable
- System owners who can agree what each job family should have, and what it should not
- Technical accounts in SAP, warehouse and till systems, VPN, telephony, facilities, procurement
- Your licensing position for Microsoft Entra ID Governance or Microsoft Entra Suite
Stages
Discovery
Event types, systems, existing checklists and the real lead times per country
Role design
Job families mapped to access profiles, approval owners, out-of-profile rules
Build
Lifecycle workflows, Logic Apps extensions, robots, the Maestro case, Teams touchpoints
Validation
Dry runs on historical joiners, movers and leavers; revocation tested against your evidence needs
Go-live
One country first, with the manual checklist alongside until the numbers agree
Optimisation
Reconciliation findings feed the profile catalogue; further systems join the pattern
Enterprise. Effort is driven by the number of target systems without a connector, how many job families need distinct profiles, and the quality of the HR data.
A warehouse supervisor who left in March still signs in through the VPN.
Send us the list of systems a new starter needs and your joiner, mover and leaver counts for the last three months. We come back with an outline access profile catalogue and the split between native lifecycle workflows and robot work.
Trace one leaver's access with usThe neighbouring process usually has the same problem
Managers sign off on entitlements they cannot read, and nobody withdraws what nobody uses.
View solution IT & servicesSoftware licences reconciled every monthLeavers, duplicates and dormant accounts keep their paid seats until somebody rebuilds the list by hand.
View solution HR & peoplePayroll inputs consolidated and checked before the runPayroll errors are found by the employee on payday, not by the team that built the file.
View solution IT & servicesEvery laptop accounted for, from order to wipe certificateHardware ordered by email, handed over without a record, and written off when the auditor asks.
View solution Case studyAutomated new-hire onboardingNew hires ready to work sooner — less paperwork for HR.
View case study Case studyThe HR agent on TeamsAn employee asks on Teams about leave, a certificate or a benefit.
View case studyIndustries we deliver this in most oftenManufacturing & industryRetail & e‑commerceShared services